Description
A cryptographic issue was addressed with improved integrity checks. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27. An attacker in a privileged network position may be able to modify network traffic.
Published: 2026-09-14
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Network Traffic Modification via compromised cryptographic integrity
Action: Immediate Patch
AI Analysis

Impact

A cryptographic flaw was identified in the integrity checks of Apple’s operating systems. The vulnerability allows an attacker with a privileged network position to modify intercepted traffic, potentially inserting or altering data before it reaches the target device. This weakness undermines the confidentiality and integrity of communications on the affected systems.

Affected Systems

Apple’s iOS, iPadOS, macOS, tvOS, and watchOS are impacted. The bug is resolved in the 27th revision of each platform: iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, and watchOS 27.

Risk and Exploitability

The CVSS score is not provided, and no EPSS data is available, so the quantified likelihood of exploitation is unknown. The vulnerability is not listed in CISA’s KEV catalog. An attacker must have foothold in a privileged network segment to use this flaw, suggesting a limited but non‑negligible attack surface. The potential impact is the ability to tamper with network traffic destined for or originating from Apple devices, which could lead to data injection or compromise of secure communications.

Generated by OpenCVE AI on September 15, 2026 at 08:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest OS updates—iOS 27, iPadOS 27, macOS Golden Gate 27, tvOS 27, and watchOS 27—to eliminate the cryptographic integrity flaw
  • Ensure that Apple devices in privileged network environments use additional encryption layers (e.g., VPN) or restrict direct network access until the firmware update is applied
  • Configure network monitoring to detect anomalous packet modifications or integrity check failures in traffic to and from Apple devices

Generated by OpenCVE AI on September 15, 2026 at 08:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 09:15:00 +0000

Type Values Removed Values Added
Title Cryptographic Integrity Failure Allowing Network Traffic Modification in Apple Operating Systems
Weaknesses CWE-327

Tue, 15 Sep 2026 02:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple watchos
Vendors & Products Apple
Apple ios And Ipados
Apple macos
Apple tvos
Apple watchos

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A cryptographic issue was addressed with improved integrity checks. This issue is fixed in iOS 27 and iPadOS 27, macOS Golden Gate 27, tvOS 27, watchOS 27. An attacker in a privileged network position may be able to modify network traffic.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apple

Published:

Updated: 2026-09-14T20:50:12.835Z

Reserved: 2026-09-01T21:13:17.750Z

Link: CVE-2026-84533

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-14T21:17:29.740

Modified: 2026-09-14T21:17:29.740

Link: CVE-2026-84533

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T09:00:16Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm